VDB
Sign up
LOW

GHSA-8r88-6cj9-9fh5

auth-js Vulnerable to Insecure Path Routing from Malformed User Input

Quick fix

GHSA-8r88-6cj9-9fh5 — @supabase/auth-js: upgrade to the fixed version with the command below.

npm install @supabase/auth-js@2.70.0

Details

### Impact The library functions `getUserById`, `deleteUser`, `updateUserById`, `listFactors` and `deleteFactor` did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called.

Implementations that follow security best practice and validate user controlled inputs, such as the `userId` are not affected by this.

### Patches Strict value checks have been added to all affected functions. These functions now require that the `userId` and `factorId` parameters MUST be valid UUID (v4).

**Patched version:** >= 2.69.1

### Workarounds Implementations that follow security best practice and validate user controlled inputs, such as the `userId` are not affected by this. It is recommended that users of the auth-js library always follow security best practice and validate all inputs, before passing these to other functions or libraries.

### References https://github.com/supabase/auth-js/pull/1063

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@supabase/auth-js
Introduced in: 0Fixed in: 2.70.0
Fixnpm install @supabase/auth-js@2.70.0

References